CVE-2026-64489 is a vulnerability in Linux Kernel
Published on July 25, 2026
ALSA: ymfpci: check snd_ctl_new1() return value
In the Linux kernel, the following vulnerability has been resolved:
ALSA: ymfpci: check snd_ctl_new1() return value
snd_ctl_new1() can return NULL when memory allocation fails.
snd_ymfpci_create_spdif_controls() does not check the return value
before dereferencing kctl->id.device, which can lead to a NULL pointer
dereference.
Add NULL checks after snd_ctl_new1() calls and return -ENOMEM if any
fails.
Products Associated with CVE-2026-64489
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 1f6c520932bca5be9e8dec137fccb2fc094a80fe and below d7c71dfd4b80f0eacac2c157a8a3a4c6e8b2e0d1 is affected.
- Version c9b83ae4a1609b1914ba7fc70826a3f3a8b234db and below 91095474eea29b95c9a8bceb9b501a2702b6c55f is affected.
- Version c9b83ae4a1609b1914ba7fc70826a3f3a8b234db and below 02f33c2062c75e28abc7ad58ce86451cf3140455 is affected.
- Version c9b83ae4a1609b1914ba7fc70826a3f3a8b234db and below f6538a318947b627710b08a268bc80a48c23bde7 is affected.
- Version c9b83ae4a1609b1914ba7fc70826a3f3a8b234db and below 18ec7d7785be7a4ee8ea11e355122282caad4267 is affected.
- Version c9b83ae4a1609b1914ba7fc70826a3f3a8b234db and below e64d170346d00b580c0043de3e5ccb3e331c47d4 is affected.
- Version cf671d2462d9af50c328bcc185d2c7b9726f8093 is affected.
- Version 6.1.34 and below 6.1.178 is affected.
- Version 6.3.8 and below 6.4 is affected.
- Version 6.4 is affected.
- Before 6.4 is unaffected.
- Version 6.1.178, <= 6.1.* is unaffected.
- Version 6.6.145, <= 6.6.* is unaffected.
- Version 6.12.96, <= 6.12.* is unaffected.
- Version 6.18.39, <= 6.18.* is unaffected.
- Version 7.1.4, <= 7.1.* is unaffected.
- Version 7.2-rc1, <= * is unaffected.